nTimetools Logo

nTimetools

0
Free
Updated 11 March 2025
Visit Website

nTimetools is a suite of console tools developed to work with timestamps in Windows. nTimetools comprises 2 tools that allow both forensic analysts as well as red teamers to modify and verify file timestamps up to 100-nanosecond precision. nTimeview allows forensic analysts to view the MACB timestamps of files on a live system. It uses the undocumented NtQueryInformationFile API. As such, it works on NTFS/FAT and even mapped drives. It does not require privileged access. nTimestomp allows red teamers to timestomp MACB timestamps of files with 100-nanosecond level precision. Forensic analysts are usually taught to spot 0s in the millisecond position as evidence that timestomping has occurred.

FEATURES

SIMILAR TOOLS

mac_apt is a versatile DFIR tool for processing Mac and iOS images, offering extensive artifact extraction capabilities and cross-platform support.

Truehunter is a tool designed to detect encrypted containers with a focus on Truecrypt and Veracrypt, utilizing a fast and memory efficient approach.

A tool for parsing and extracting information from the Master File Table of NTFS file systems.

Tool for parsing Android logs events and protobuf data

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.

ForensicMiner, Redefine DFIR Automations

dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.

Automated tool for parsing Windows registry hives and extracting valuable information for forensic analysis.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

Copyright © 2025 - All rights reserved